Lucene search

K
cve[email protected]CVE-2003-0874
HistoryNov 17, 2003 - 5:00 a.m.

CVE-2003-0874

2003-11-1705:00:00
web.nvd.nist.gov
22
cve-2003-0874
deskpro
sql injection
faq.php
view.php
unauthorized activities
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

8.2 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.3%

Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and earlier allow remote attackers to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.php, and (4) the Password entry on the logon screen.

Affected configurations

NVD
Node
deskprodeskproMatch1.1_.0
CPENameOperatorVersion
deskpro:deskprodeskproeq1.1_.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

8.2 High

AI Score

Confidence

Low

0.007 Low

EPSS

Percentile

80.3%

Related for CVE-2003-0874